33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2022-44789
Software Genérico Web
8.8
HIGH
EPSS
2.9%
2022 1 PoC

A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

CVE-2022-47875
Software Genérico Web
8.8
HIGH
EPSS
23.0%
2022 1 PoC

A Directory Traversal vulnerability in /be/erpc.php in Jedox GmbH Jedox 2020.2.5 allows remote authenticated users to execute arbitrary code.

CVE-2022-48604
SL 1 Database
8.8
HIGH
EPSS
0.1%
2022 CWE-78 1 PoC

A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled input and passes it directly to a SQL query. This allows for the injection of arbitrary SQL before being executed against the database.

CVE-2022-26927
Windows 10 Version 1809 Windows
8.8
HIGH
EPSS
28.1%
2022 2 PoCs

Windows Graphics Component Remote Code Execution Vulnerability

CVE-2022-4237
Welcart e-Commerce Web Windows
8.8
HIGH
EPSS
1.2%
2022 1 PoC

The Welcart e-Commerce WordPress plugin before 2.8.6 does not validate user input before using it in file_exist() functions via various AJAX actions available to any authenticated users, which could allow users with a role as low as subscriber to perform PHAR deserialisation when they can upload a file and a suitable gadget chain is present on the blog

CVE-2022-34756
Easergy P5 Web
8.8
HIGH
EPSS
1.9%
2022 CWE-120 1 PoC

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)

CVE-2022-42221
Software Genérico General
8.8
HIGH
EPSS
2.6%
2022 1 PoC

Netgear R6220 v1.1.0.114_1.0.1 suffers from Incorrect Access Control, resulting in a command injection vulnerability.

CVE-2022-34468
Firefox Web
8.8
HIGH
EPSS
0.5%
2022 1 PoC

An iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVE-2022-2067
francoisjacquet/rosariosis Database
8.8
HIGH
EPSS
0.8%
2022 CWE-89 1 PoC

SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.

CVE-2022-24724
cmark-gfm General
8.8
HIGH
EPSS
4.2%
2022 CWE-190 1 PoC

cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's marker rows contain more than UINT16_MAX columns. The impact of this heap corruption ranges from Information Leak to Arbitrary Code Execution depending on how and where `cmark-gfm` is used. If `cmark-gfm` is used for rendering remote user controlled markdown, this vulnerability may lead to Remote Code Execution (RCE) in

CVE-2022-38065
OpenStack DevOps
8.8
HIGH
EPSS
0.2%
2022 CWE-269 1 PoC

A privilege escalation vulnerability exists in the oslo.privsep functionality of OpenStack git master 05194e7618 and prior. Overly permissive functionality within tools leveraging this library within a container can lead increased privileges.

CVE-2022-45923
Software Genérico General
8.8
HIGH
EPSS
3.1%
2022 3 PoCs

An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The Common Gateway Interface (CGI) program cs.exe allows an attacker to increase/decrease an arbitrary memory address by 1 and trigger a call to a method of a vftable with a vftable pointer value chosen by the attacker.

CVE-2022-27641
R6700v3 Networking
8.8
HIGH
EPSS
0.3%
2022 CWE-190 1 PoC

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-15806.

CVE-2022-44384
Software Genérico Web
8.8
HIGH
EPSS
48.7%
2022 1 PoC

An arbitrary file upload vulnerability in rconfig v3.9.6 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-21442
GoldenGate Database
8.8
HIGH
EPSS
0.2%
2022 1 PoC

Vulnerability in Oracle GoldenGate (component: OGG Core Library). The supported version that is affected is Prior to 23.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle GoldenGate executes to compromise Oracle GoldenGate. While the vulnerability is in Oracle GoldenGate, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:

CVE-2022-40282
Software Genérico General
8.8
HIGH
EPSS
0.8%
2022 2 PoCs

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.

CVE-2022-33012
Software Genérico General
8.8
HIGH
EPSS
1.6%
2022 1 PoC

Microweber v1.2.15 was discovered to allow attackers to perform an account takeover via a host header injection attack.

CVE-2022-26943
Mobile Radio General
8.8
HIGH
EPSS
0.2%
2022 CWE-338 1 PoC

The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an adversary can derive the contents of the entropy pool by an exhaustive search of possible values, based on an observed authentication challenge. Second, an adversary can use knowledge of the entropy pool to predict authentication challenges. As such, the unit is vulnerable to CVE

CVE-2006-2492
🔥 KEV Software Genérico General
8.8
HIGH
EPSS
74.1%
2006 2 PoCs

Buffer overflow in Microsoft Word in Office 2000 SP3, Office XP SP3, Office 2003 Sp1 and SP2, and Microsoft Works Suites through 2006, allows user-assisted attackers to execute arbitrary code via a malformed object pointer, as originally reported by ISC on 20060519 for a zero-day attack.

CVE-2006-3730
Software Genérico Windows
8.8
HIGH
EPSS
86.9%
2006 2 PoCs

Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.